-
Notifications
You must be signed in to change notification settings - Fork 32
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
(SIMP-8616) Firewall doc updates (#406)
Changed: - Updated the changelog docs to note that firewalld is now the default for new installations Added: - Added a HOWTO for fully disabling the system firewall SIMP-8616 #comment related doc updates Co-authored-by: op-ct <chris.tessmer@onyxpoint.com> Co-authored-by: lnemsick-simp <lnemsick-simp@users.noreply.github.com>
- Loading branch information
1 parent
b476fe6
commit dfeb9db
Showing
3 changed files
with
34 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,28 @@ | ||
.. _howto-disable-the-firewall: | ||
|
||
Fully Disabling the System Firewall | ||
=================================== | ||
|
||
Though we hope that you never actually want to do this, there may be situations where you want to | ||
use puppet to fully disable the system firewall. | ||
|
||
When :program:`iptables` was the only option, this was very straightforward. The introduction of | ||
:program:`firewalld` has added a bit of complexity due to the preservation of backwards | ||
compatibility with calls into the :code:`iptables::rules::*` :term:`defined types`. | ||
|
||
To fully disable **all** firewalls on the system (not just management of the firewalls) set the | ||
following via :term:`Hiera`: | ||
|
||
.. code-block:: yaml | ||
iptables::enable: false | ||
firewalld::service_enable: false | ||
firewalld::service_ensure: 'stopped' | ||
As per usual, once this is set, Puppet will ensure that the firewall is fully disabled until the | ||
settings are reversed. | ||
|
||
.. IMPORTANT:: | ||
|
||
Just setting :code:`firewalld::service_enable: false` will likely cause your system to fall back | ||
to using :program:`iptables`. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters